Discourse是一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 2.9.0.beta14版本存在信息泄露漏洞。攻击者利用该漏洞暴露隐私信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-22454 | 8.0 HIGH | Discourse vulnerable to Cross-site Scripting through pending post titles descriptions |
| CVE-2023-22455 | 6.8 MEDIUM | Discourse vulnerable to Cross-site Scripting through tag descriptions |
| CVE-2022-23548 | 6.5 MEDIUM | Discourse 跨站脚本漏洞 |
| CVE-2022-46177 | 5.7 MEDIUM | Discourse password reset link can lead to in account takeover if user changes to a new ema |
| CVE-2022-23549 | 5.7 MEDIUM | Discourse vulnerable to bypass of post max_length using HTML comments |
| CVE-2023-22453 | 5.3 MEDIUM | Discourse vulnerable to exposure of user post counts per topic to unauthorized users |
| CVE-2022-46168 | 3.5 LOW | Group SMTP user emails are exposed in CC email header |
No comments yet